SECURITY % min read

Apple’s paid privacy tools face another embarrassing security issue

Apple’s paid privacy tools face another embarrassing security issue
Photo by Bangyu Wang / Unsplash

Apple’s iCloud Private Relay, a paid privacy feature meant to hide users’ IP addresses in Safari, is leaking real IPs due to multiple flaws in WebKit. Security researchers Talal Haj Bakry and Tommy Mysk discovered that DNS prefetching, WebAuthn Related Origin Requests, and WebTransport bypass proxy protections, exposing users’ IP addresses directly to websites. The most serious issue involves WebAuthn, where passkey‑related requests are sent from the device itself, revealing the true IP without any user prompt. Additional leaks appeared in iOS 26 and 26.4, allowing DNS and HTTP/3 connections to bypass Private Relay entirely. The flaws also affect proxy‑based privacy browsers like Psylo and Onion Browser, though some mitigations exist. Apple has acknowledged the report and plans to fix the issues in fall 2026. The incident follows another recent privacy embarrassment involving Hide My Email, raising concerns about the reliability of Apple’s paid privacy tools.

Read the full story on TechSpot →